Files
roboco/docs/deploy/env-reference.md
T
a8cb2470ba v0.15.0: Metrics granularity — per-member / per-task / org + CEO scorecards (#289)
* feat(metrics): capture per-session turns + tool_calls (phase 1)

Persist LLM iterations (turns) and tool invocations per agent spawn session,
the raw signal the granular per-member performance metrics build on (real
effort/iterations vs wall-clock).

- sum_transcript_usage returns a 5-tuple adding turns = unique assistant
  message-id count; _usage_from_transcript + _resolve_active_tokens updated to
  the 5-tuple (active-tokens keeps its 4-tuple contract by slicing).
- SDK: _SessionState.turns, set by /usage/sync; /usage/status (TokenUsageStatus)
  now carries turns + tool_calls (= total_calls).
- orchestrator: new _resolve_final_turns_tools (SDK primary, transcript fallback
  for turns only; Grok -> 0/0) wired into _finalize_spawn_session, which writes
  turns + tool_calls to agent_spawn_sessions.
- migration 055 adds turns + tool_calls (BigInteger DEFAULT 0 -> historical/Grok
  rows read 0, surfaced as n/a). Verified real alembic upgrade/downgrade.

Part of metrics-granularity (v0.15.0); recon-adjusted plan on disk.

* feat(metrics): pure compute_stage_effort helper (phase 2, part 1)

Foundation-layer overlap math (no DB): split each task status window into
active (merged wall-clock overlap of spawn stints — concurrent stints counted
once, so active <= window) vs wait (queue/review idle). Distinct from summed
effort. The per-task metrics service will feed it audit-log windows + spawn
stints. 9 unit tests (disjoint/nested/partial/merged/clamped/zero/multi-window).

* feat(metrics): per-task live metrics + GET /metrics/task/{id} (phase 2)

TaskMetrics dataclass + MetricsService.get_task_metrics: summed spawn effort
(vs wall-clock), turns/tool_calls/tokens/cost, per-stage active-vs-wait
(compute_stage_effort over audit windows x spawn stints), and who-caused-rework
(revision_count + named qa/pr fail events). Open stints and the open final
stage window close at completed_at for a terminal task (else now), so stages
don't grow past completion. Exposed at GET /dashboard/metrics/task/{task_id}
(404 if absent). Real-PG tests (compose/none/in-flight) + route tests (200/404).

* feat(metrics): CEO-as-member scorecard + ceo_reject audit regression (phase 3)

The human CEO is a measured member, read purely from audit_log (agent_role='ceo'
serializes from the CEO StrEnum): approval dwell (awaiting_ceo_approval -> a CEO
decision, incl. the coordination-root reject that lands in pending), unblock
dwell (blocked -> a CEO revive), and god-mode action count (every CEO-attributed
transition). CeoScorecard + MetricsService.get_ceo_scorecard (p50/p90 via
PERCENTILE_CONT, expanding IN for the decision sets) + GET
/dashboard/metrics/member/ceo (declared before any future member/{id} route).

The ceo_reject coordination-root audit gap the plan meant to close was already
closed by the gap-sweep (routes through admin_set_status -> agent_role='ceo'
audit); locked with a regression assertion in the existing coordination-reject
test. Real-PG tests: approval/unblock/godmode, non-ceo exclusion, empty->zeros.

* feat(metrics): audit instrumentation for escalations/blocked-others/idle (phase 4a)

The three extra per-member metrics that had no data source get durable,
in-session audit events (additive; never gate the underlying action):
- apply_escalation -> task.escalated (details.escalator_slug) on both the
  normal block path and the pool-divert path -> escalations count.
- _unblock_dependents -> task.unblocked_dependents (details.count) on the
  completed BLOCKER task, captured before the dependency edges are pruned ->
  blocked-others count (sweeper attributes to the blocker's owner).
- mark_agent_idle -> agent.idle (details.agent_slug) -> idle/utilization (the
  sweeper pairs an idle mark to the member's next spawn for idle duration).
(QA pass-rate needs no new event — reuses task.awaiting_documentation[qa] +
task.qa_fail.) Real-PG tests for each; 111 transition tests still green.

* feat(metrics): member_performance_daily rollup table + migration 056 (phase 4b)

The per-member scorecard rollup: one row per (date, member_kind, agent_slug),
CEO as a first-class member_kind='ceo' row (agent_slug='' NOT NULL so the
NULL-distinct UNIQUE keeps it unique). Full column set + the four CEO-approved
extras (qa_reviews_total/passed, escalations, blocked_others, idle_seconds) plus
blocked_seconds. Overwrite-upsert on (date, member_kind, agent_slug) for an
idempotent sweep. Migration 056 verified real up/down (24 cols, 4 indexes).

* feat(metrics): _sweep_member_performance rollup sweeper (phase 4c)

The daily per-member rollup sweep (mirrors _sweep_daily_rollup): a trailing
7-day, idempotent overwrite-upsert wired into _run_sweep. One focused query per
metric merges into a (date, agent_slug) accumulator — spawn effort/turns/tokens/
cost, completed/first-pass/revisions-received, revisions-caused (qa/pr fails),
QA pass-rate (passed + total), escalations (by escalator_slug), blocked-others
(unblocked_dependents by blocker owner), idle_seconds (idle mark -> next spawn),
blocked_seconds (blocked dwell) — plus one CEO row/day (approval/unblock dwell +
god-mode). Real-PG test asserts every facet + idempotency (a 2nd sweep
overwrites, never doubles); spawn-day != completion-day split is by-design.

* feat(metrics): member/org rollup scorecards + endpoints + live overlay (phase 5)

MemberScorecard + OrgScorecard with derived rates (FPY, effort-throughput,
turns/tool-calls per task, QA pass-rate, utilization) — all division-guarded to
None. get_member_scorecard reads member_performance_daily by slug and overlays
the member's live in-flight (non-terminal) tasks' effort via get_task_metrics
(disjoint by status: completion counts stay rollup-only, overlay only enriches
effort/turns/cost; includes_live_inflight flags it). get_org_scorecard
aggregates the cell (?team=) or whole org. Routes: GET /metrics/member/{agent_id}
(404 if absent, after the ceo literal route) + GET /metrics/org?team=. Real-PG
tests (derived rates, overlay no double-count, guards, org) + route tests.

* feat(metrics): granular CEO completion notification (phase 6)

There was no CEO completion notification at all (EventType.TASK_COMPLETED was
defined but never emitted). Add notify_ceo_of_completion in
NotificationDeliveryService — a granular body (real effort vs wall-clock +
stints/turns/tool-calls/revisions[QA/PR]/cost from get_task_metrics; degrades to
wall-clock-only, turns 'n/a', when there are no spawn sessions). Reuses the
existing ALERT type (no enum migration; the notificationtype PG enum is fixed at
001). ceo_approve now emits TASK_COMPLETED + fires the notification (best-effort
via _notify_completion — never blocks completion); complete() emits
TASK_COMPLETED too (closes the dead-code gap; the WS bridge can forward it).
Pure formatter tests + real-PG notification test.

* [metrics-granularity] Phase 7: panel Scorecards tab + dashboard overview

Add the CEO-facing metrics surfaces for the granularity feature:

- New "Scorecards" tab on the Metrics page: org rollup headline, the
  CEO-as-member card (approval/unblock dwell + god-mode count), and a
  per-member table (completed, first-pass yield, active effort, turns/task,
  QA pass-rate, escalations, blocked-others, utilization). Each member row
  self-fetches its rollup scorecard; live in-flight rows carry a "live" badge.
- New dashboard overview card (ScorecardOverviewPanel): org-wide 30-day
  headline (completed, FPY, throughput/hr, active effort, cost) deep-linking
  into the Scorecards tab.
- Plumbing: TaskMetrics/MemberScorecard/OrgScorecard/CeoScorecard types,
  observability API client methods + empty fallbacks, and the four
  useCeoScorecard/useMemberScorecard/useOrgScorecard/useTaskMetrics hooks.

Panel gate green: tsc, eslint, prettier, vitest (175 tests, +6 new).

* [metrics-granularity] test: make completion-notification robust to shared-DB CEO

test_notify_ceo_of_completion_creates_alert errored in the full suite (passed
in isolation): the session-scoped test DB is shared across the run, and the
sibling real-DB board-gate test commits a role=CEO agent (slug="ceo") without
cleanup — so my env fixture's hardcoded slug="ceo" insert hit a unique-constraint
violation, and a second role=CEO row would also make _get_ceo_agent()'s
scalar_one_or_none() raise. Reuse an existing CEO when present (the singleton the
production system actually has), else create one with a unique slug. Order-
independent. Also reflow test_metrics_instrumentation.py to ruff format.

* chore(release): 0.15.0

Metrics granularity: per-member/per-task/org + CEO-as-member scorecards,
turn/tool-call capture (migration 055), member_performance_daily rollup
(migration 056) with QA pass-rate / escalations / blocked-others / utilization,
per-task active-vs-wait metrics, granular completion notification, panel
Scorecards tab + dashboard Performance card, and the ceo_reject audit fix.

Version bump across the canonical set + CHANGELOG.

* [metrics-granularity] fix pre-tag audit findings (overlay double-count + panel error states)

Adversarial review before the v0.15.0 tag surfaced two real logical gaps:

- MAJOR (backend): the live in-flight overlay re-summed ALL sessions of every
  non-terminal task via get_task_metrics, but _msweep_spawn already rolls up
  every CLOSED session regardless of task status — so a closed session on a
  still-open task was counted twice (rollup + overlay), permanently inflating a
  member's effort/turns/tokens/cost on the common reap/respawn path. The overlay
  now sums only OPEN sessions (ended_at IS NULL), which the closed-only rollup
  can never contain — disjoint by construction. A just-closed session lands in
  the rollup on the next ~60s sweep (no gap of note). Aggregated in SQL to mirror
  _msweep_spawn. Regression test reproduces the double-count (turns 10→5).

- MAJOR (panel): the four new scorecard surfaces used `isLoading || !data` with
  no isError branch, so a failed query span forever on a skeleton. They now
  surface a load error. Tests added.

Also: OrgSummary active-effort formatting no longer round-trips hours→seconds→
hours; dashboard grid uses xl:grid-cols-4 (was 2xl) so 4 panels show at 1280px;
corrected the inaccurate "NULL distinct" CEO-row uniqueness comment (agent_slug
is NOT NULL; the '' tuple is simply distinct from agent rows).

make quality GREEN (cov 95.31%); panel GREEN (vitest 178).

* [metrics-granularity] fix: decode bytes stream message-id before XCLAIM

StreamEventBus._recover_stream passed the pending message id to XCLAIM via
str() on the raw bytes the client returns (redis client has no
decode_responses), producing "b'1782066556728-0'". Redis rejects that with
"Unrecognized XCLAIM option", so pending-message recovery threw on every
reclaim tick and unacked messages from crashed/slow consumers were never
reclaimed (leaking in the PEL on every stream, spamming the error log). Decode
via the existing _to_str helper — the fix the sibling claim path already uses.

Pre-existing in v0.14.0 (unrelated to metrics granularity); folded into this
release per CEO. TDD regression test + CHANGELOG entry. make quality GREEN.

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
2026-07-01 05:18:45 +02:00

22 KiB
Raw Blame History

Environment reference

This is the canonical list of every ROBOCO_* setting. They are all read by a single Pydantic-Settings class (roboco/config.py), loaded from the process environment and .env, prefixed with ROBOCO_, and case-insensitive. Most have a working default; the few that don't, and the ones the orchestrator refuses to start without, are flagged below.

!!! tip "You rarely set most of these" For a working deploy you set the two required secrets, the host paths, and maybe a feature flag or two. The long tables here exist so that when you do need to tune a timeout or a window, you can find it. The defaults shown are RoboCo's config defaults; a few compose-only defaults differ and are called out.

A feature flag set in .env takes effect on the next backend restart. The env-gated subsystems can also be toggled from the panel's Settings → Feature Flags card, which persists to the settings store and overrides the env default; an unset toggle falls back to the env/config default. See the Optional capabilities section for what each subsystem does.

Required secrets

Variable Default Purpose
ROBOCO_ENCRYPTION_KEY (empty — required) Fernet key encrypting every per-project git token at rest. The orchestrator refuses to start without it (compose :? guard). Generate with python -c 'from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())'. Keep it stable — losing it makes stored tokens undecryptable.
ROBOCO_AGENT_AUTH_SECRET (empty — required for compose) HMAC secret signing the per-agent X-Agent-Token. Generate with python -c 'import secrets; print(secrets.token_hex(32))'.

Security & auth

Variable Default Purpose
ROBOCO_AGENT_AUTH_REQUIRED false Fail-closed secure mode. When true, every API call must carry a valid token. Requires ROBOCO_PANEL_AGENT_TOKEN to keep the panel working. On a trusted LAN, leave false (header-trust mode).
ROBOCO_PANEL_AGENT_TOKEN (empty) The CEO token nginx injects as X-Agent-Token on /api and /ws in secure mode, so the panel works without the browser holding the signing secret. Generate with make panel-token.

Application & API server

Variable Default Purpose
ROBOCO_APP_VERSION 0.15.0 Reported app version.
ROBOCO_DEBUG false Debug mode.
ROBOCO_ENVIRONMENT development One of development / staging / production. Selects the JSON log renderer (prod) vs console renderer. The compose stack sets production.
ROBOCO_HOST 127.0.0.1 Bind address. Use 0.0.0.0 in containers.
ROBOCO_PORT 8000 API port.
ROBOCO_API_URL (unset) Override base URL for containerized agents (e.g. http://roboco-orchestrator:8000); otherwise built from host/port.
ROBOCO_CORS_ORIGINS ["http://localhost:3000","http://localhost:5173"] Allowed CORS origins. The single-origin nginx setup means you rarely change this.
ROBOCO_CORS_ALLOW_CREDENTIALS true Whether CORS allows credentials.
ROBOCO_PUBLIC_BASE_URL http://127.0.0.1:8000 Reachable base URL embedded in commit-trailer links — set to your LAN IP or domain so the links resolve.

Database

Variable Default Purpose
ROBOCO_DATABASE_HOST localhost Postgres host (roboco-postgres in compose).
ROBOCO_DATABASE_PORT 5432 Postgres port.
ROBOCO_DATABASE_USER roboco Postgres user.
ROBOCO_DATABASE_PASSWORD roboco Postgres password — change it for any real deployment.
ROBOCO_DATABASE_NAME roboco Database name.
ROBOCO_DATABASE_ECHO false Log every SQL statement.
ROBOCO_DATABASE_POOL_SIZE 10 Connection pool size.
ROBOCO_DATABASE_MAX_OVERFLOW 20 Extra connections beyond the pool.
ROBOCO_DATABASE_POOL_TIMEOUT 10 Seconds to wait for a pooled connection.
ROBOCO_DATABASE_POOL_RECYCLE 1800 Recycle a connection after this many seconds.

Redis

Variable Default Purpose
ROBOCO_REDIS_HOST localhost Redis host (roboco-redis in compose).
ROBOCO_REDIS_PORT 6379 Redis port.
ROBOCO_REDIS_DB 0 Redis logical DB.
ROBOCO_REDIS_PASSWORD (unset) Optional Redis password.

RAG, embeddings & Ollama

Variable Default Purpose
ROBOCO_RAG_PERSIST_DIR .roboco Local RAG persistence dir.
ROBOCO_RAG_CHUNK_STRATEGY fixed One of fixed / semantic / hierarchical / contextual. fixed recommended; semantic loads an extra model.
ROBOCO_RAG_CHUNK_SIZE 512 Base chunk size.
ROBOCO_RAG_CHUNK_SIZE_DOCS 1536 Chunk size for docs.
ROBOCO_RAG_CHUNK_SIZE_JOURNALS 1024 Chunk size for journals/reflections.
ROBOCO_RAG_CHUNK_OVERLAP 128 Chunk overlap.
ROBOCO_RAG_AUTO_UPDATE_ENABLED true Whether the RAG index auto-refreshes.
ROBOCO_RAG_AUTO_UPDATE_INTERVAL 300 Seconds between auto-updates.
ROBOCO_ANTHROPIC_API_KEY (unset) Optional Anthropic key. Agents use the mounted Claude Code auth, not a metered key.
ROBOCO_DEFAULT_EMBEDDING_MODEL qwen3-embedding:0.6b Embedding model (1024-dim).
ROBOCO_EMBEDDING_DIMENSIONS 1024 Embedding dimensions — must match the model.
ROBOCO_LOCAL_LLM_MODEL glm-5.2:cloud Local LLM for RAG answer synthesis.
ROBOCO_LOCAL_LLM_BASE_URL http://roboco-ollama:11434/v1 Ollama OpenAI-compatible endpoint.
ROBOCO_OLLAMA_BASE_URL http://roboco-ollama:11434 Ollama native endpoint (embeddings, model management).

Workspaces & git timeouts

Variable Default Purpose
ROBOCO_WORKSPACES_ROOT /data/workspaces Root for all agent git clones.
ROBOCO_WORKSPACE_AUTO_CLONE true Auto-clone a repo on first workspace access.
ROBOCO_WORKSPACE_CLONE_TIMEOUT 300 Seconds for a git clone.
ROBOCO_WORKSPACE_REFRESH_FETCH_TIMEOUT_SECONDS 60 Timeout for the best-effort git fetch on re-entry into a healthy clone.
ROBOCO_WORKSPACE_INSTALL_DEV_DEPS true After cloning, install the project's dev dependencies into the workspace so make quality runs without re-downloading tooling.
ROBOCO_WORKSPACE_DEP_INSTALL_TIMEOUT_SECONDS 600 Timeout for that post-clone dependency install.
ROBOCO_GIT_COMMAND_TIMEOUT_SECONDS 30 Timeout for a single local git subprocess (status, log, checkout).
ROBOCO_GIT_COMMIT_TIMEOUT_SECONDS 180 Timeout for staging + committing a changeset.
ROBOCO_GIT_NETWORK_TIMEOUT_SECONDS 120 Timeout for git ops that talk to origin (fetch / pull / push).
ROBOCO_PROTECTED_GIT_URLS (empty) Repo URL substrings a project may not point at — blocks agent commits/merges from reaching a protected repo.
ROBOCO_SESSION_IDLE_TIMEOUT_SECONDS 3600 Idle seconds before a messaging session is swept closed.

Agent images (spawn source)

Variable Default Purpose
ROBOCO_AGENT_IMAGE_REGISTRY (empty) Registry namespace for pre-built agent images (e.g. ghcr.io/rennf93). Empty = build locally. The registry compose wires this to ROBOCO_REGISTRY.
ROBOCO_AGENT_IMAGE_TAG (empty) Tag for pre-built agent images (e.g. 0.9.0). Empty = implicit :latest. The registry compose wires this to ROBOCO_VERSION.

!!! note "Deploy-time variables (compose, not config.py)" A few variables are consumed by the compose files and host-mount wiring rather than by config.py: ROBOCO_REGISTRY, ROBOCO_VERSION, ROBOCO_DATA_DIR, ROBOCO_HOST_PROJECT_DIR, ROBOCO_HOST_CLAUDE_DIR / CLAUDE_AUTH_DIR, ROBOCO_HOST_DATA_DIR, and ROBOCO_HOST_GROK_DIR. They are documented in the production deploy reference.

Transcript retention

Variable Default Purpose
ROBOCO_TRANSCRIPT_RETENTION_DAYS 14 Days to keep agent Claude Code transcripts. A stored panel setting overrides this default.
ROBOCO_TRANSCRIPT_PRUNE_ENABLED true Whether the background sweep prunes old transcripts.
ROBOCO_TRANSCRIPT_PRUNE_INTERVAL_SECONDS 3600 Minimum seconds between prune passes.

Spawn pacing, SLAs & reaper windows

The orchestrator's dispatcher uses these to pace spawns, detect loops, and reclaim stuck work. Defaults are tuned for real LLM latency — raise the reaper windows (not lower) if long agent tasks are being reaped mid-work.

Variable Default Purpose
ROBOCO_AGENT_TOOL_CALL_WARN 50 Soft warning threshold for per-session tool calls.
ROBOCO_AGENT_TOOL_CALL_HALT 150 Hard cap on per-session tool calls; the orchestrator stops the container.
ROBOCO_AGENT_LOOP_THRESHOLD 3 Identical tool+args repeats in the window that flag a loop.
ROBOCO_AGENT_LOOP_WINDOW 10 How many recent tool calls to inspect for loop detection.
ROBOCO_AGENT_STOP_ATTEMPT_ALLOWANCE 1 Stop-without-terminal attempts before auto-substitute.
ROBOCO_AGENT_SLA_DEVELOPER_IN_PROGRESS 7200 SLA (s) for a developer in in_progress.
ROBOCO_AGENT_SLA_DEVELOPER_VERIFYING 1800 SLA (s) for a developer in verifying.
ROBOCO_AGENT_SLA_QA_CLAIMED 1800 SLA (s) for QA on a claimed review.
ROBOCO_AGENT_SLA_DOCUMENTER_CLAIMED 3600 SLA (s) for a documenter on a claimed task.
ROBOCO_AGENT_SLA_CELL_PM_CLAIMED 14400 SLA (s) for a cell PM on a claimed task.
ROBOCO_CLAIM_STALE_SECONDS 180 Claim-heartbeat staleness used by the spawn trigger filter.
ROBOCO_STALE_CLAIM_REAP_SECONDS 600 Reaper-only stale-claim threshold before releasing a claim back to pending.
ROBOCO_PM_CLOSURE_RECENTLY_PAUSED_SECONDS 45 Debounce before respawning a PM to close a recently paused parent.
ROBOCO_GROK_IDLE_KILL_SECONDS 900 Idle-container kill threshold for Grok agents (they emit no SDK heartbeat).
ROBOCO_GROK_MAX_COST_USD 0.0 Per-agent Grok cost ceiling (USD) before kill; 0 disables.
ROBOCO_INTERACTIVE_IDLE_REAP_SECONDS 1800 Idle-reap threshold for live intake/secretary chats; 0 disables.
ROBOCO_CLAIMED_NO_AGENT_GRACE_SECONDS 120 Grace window before respawning/releasing a claimed task with no running agent.
ROBOCO_PM_DECISION_WINDOW_SECONDS 300 Recency window for a PM journal:decision to satisfy gating verbs.
ROBOCO_SPAWN_COOLDOWN_SECONDS 60 Per-task spawn-rate cooldown.
ROBOCO_ROLE_SPAWN_RATE_PER_MINUTE 6 Per-role spawn-rate limit per minute.

Gateway: manifests & tracing-gate minimums

Variable Default Purpose
ROBOCO_MANIFEST_HOST_DIR /app/manifests Orchestrator dir where per-agent tool manifests are written; must be a host-bind-mounted path so the daemon can mount each manifest into its agent.
ROBOCO_QA_NOTES_MIN_CHARS 80 Minimum characters for QA notes.
ROBOCO_DOCS_NOTES_MIN_CHARS 20 Minimum characters for docs notes.
ROBOCO_DEV_NOTES_MIN_CHARS 40 Minimum characters for a developer's dev_notes.
ROBOCO_PR_REVIEWER_NOTES_MIN_CHARS 40 Minimum characters for a PR reviewer's notes.
ROBOCO_QUICK_CONTEXT_MIN_CHARS 30 Minimum characters for a PM's quick_context resumption section.
ROBOCO_COMMIT_SUBJECT_MIN_CHARS 20 Minimum characters for a commit subject.
ROBOCO_COMMIT_BANNED_WORDS wip,tmp,asdf,oops,fix,update,change,stuff,things Banned single-word commit subjects.

Grok runtime

Only relevant if you run any agent on Grok. See the models section for the full runtime.

Variable Default Purpose
ROBOCO_HOST_GROK_DIR /home/renzof/.grok (compose) Host ~/.grok SuperGrok auth dir; mounted read-write into the orchestrator (token auto-refresh) and read-only into Grok agents. The same value is both the source and target path.
ROBOCO_GROK_AGENT_IMAGE roboco-agent-grok:latest Image the orchestrator spawns for Grok agents.
ROBOCO_GROK_CLI_MODEL grok-build Grok CLI model id.
ROBOCO_GROK_REASONING_EFFORT (empty) low/medium/high/xhigh/max for all Grok agents; empty keeps the model default.
ROBOCO_GROK_MAX_TURNS 200 Hard ceiling on agentic turns per Grok run (loop guard).
ROBOCO_GROK_IDLE_KILL_SECONDS 900 (see reaper table) Idle-kill window for a wedged Grok container.
ROBOCO_GROK_MAX_COST_USD 0.0 (see reaper table) Per-agent Grok cost ceiling.

Optional subsystem flags (default-off unless noted)

These gate the env-toggled capabilities. Each is inert when off. See Optional capabilities.

Web research — default on

Variable Default Purpose
ROBOCO_RESEARCH_ENABLED true Master switch for web research. When false, the search MCP is not mounted into any agent.
ROBOCO_RESEARCH_PROVIDER tavily tavily / brave / exa / null.
ROBOCO_RESEARCH_API_KEY (unset) Provider key — server-side only, never reaches an agent. Unset = empty-result null provider.
ROBOCO_RESEARCH_MAX_RESULTS 5 Cap on results per search (120).
ROBOCO_RESEARCH_FETCH_MAX_CHARS 20000 Cap on extracted characters per fetch.
ROBOCO_RESEARCH_TIMEOUT_SECONDS 15.0 Per-request outbound timeout.
ROBOCO_RESEARCH_DAILY_QUOTA_PER_AGENT 50 Search+fetch calls per agent per UTC day.

GitHub repo provisioning — default on (inert without token/org)

Variable Default Purpose
ROBOCO_PROVISIONING_ENABLED true Master switch for pitch auto-provisioning. Inert with no token/org regardless.
ROBOCO_PROVISIONING_TOKEN (empty) GitHub PAT (repo + org admin) used to create repos — server-side only.
ROBOCO_PROVISIONING_ORG (empty) GitHub org where new repos are created.
ROBOCO_GITHUB_API_BASE_URL https://api.github.com Override for GitHub Enterprise.
ROBOCO_PROVISIONING_TIMEOUT_SECONDS 30.0 Per-request provisioning timeout.
ROBOCO_PROVISIONING_REPO_PRIVATE true Whether provisioned repos are private.

Architectural conventions — off (config) / on (compose)

Variable Default Purpose
ROBOCO_CONVENTIONS_ENABLED false (config) / true (compose) Master switch for the per-project conventions standard (scaffold, ambient injection, baseline constraints, gate enforcement). The compose orchestrator block defaults this on (left off in docker-compose.registry.yml); fully inert when off.

Toolchain matching — default off

Variable Default Purpose
ROBOCO_TOOLCHAIN_MATCH_ENABLED false (config) / true (compose) Provision the agent workspace with the target project's Python and block delivery gates when the suite can't run. The compose orchestrator block defaults this on.

Provider overload break — default on

Variable Default Purpose
ROBOCO_OVERLOAD_BREAK_ENABLED true Park a provider on a persistent overload (HTTP 529/500/503) the way a 429 is parked, instead of crash-retrying.
ROBOCO_GATEWAY_HEALTH_ENABLED true Probe a stale-heartbeat-but-live agent's gateway and kill + respawn it when the gateway is broken (a corrupted /app venv firing no verb), instead of the reaper protecting it forever. Off => spare live containers on verb-heartbeat liveness alone.
ROBOCO_GATEWAY_HEALTH_GRACE_SECONDS 180 How long an agent gateway may probe as broken before recovery — tolerates a transient probe miss.
ROBOCO_IMAGE_PRUNE_ENABLED true Background sweep prunes dangling (<none>) Docker images left by agent-image rebuilds, throttled ~6h. Only dangling images are removed — a tagged image or one backing a running container is never touched. Not a feature flag; disable to manage image cleanup yourself.

Strategy engine — default off

Variable Default Purpose
ROBOCO_STRATEGY_ENGINE_ENABLED false Master switch for the autonomous strategy engine (notify-only). When off the loop never runs.
ROBOCO_STRATEGY_ENGINE_INTERVAL_SECONDS 1800 Seconds between assessment passes.
ROBOCO_STRATEGY_STRANDED_BLOCKED_MINUTES 120 A task blocked longer than this is surfaced as stranded.

External / internal PR review — default off

Variable Default Purpose
ROBOCO_EXTERNAL_PR_ENABLED false (config) / true (compose) Master switch for inbound external/fork PR review. The compose orchestrator block defaults this on.
ROBOCO_EXTERNAL_PR_POLL_INTERVAL_SECONDS 300 Seconds between inbound external-PR discovery passes.
ROBOCO_EXTERNAL_PR_AUTHOR_ALLOWLIST (empty) GitHub usernames auto-trusted. Empty = every external PR needs human confirmation.
ROBOCO_EXTERNAL_PR_REQUIRE_HUMAN_CONFIRM true Require explicit human confirmation before any agent fetches/checks-out/executes external code.
ROBOCO_INTERNAL_PR_ENABLED false Also review org-repo (non-fork) PRs not tied to an active task.

Self-healing CI loop — default off

Variable Default Purpose
ROBOCO_SELF_HEAL_ENABLED false Master switch for the self-heal loop (detect + notify the CEO). When off the loop never runs.
ROBOCO_SELF_HEAL_PROJECT_SLUG (empty) / roboco-api (compose) The registered project that is RoboCo itself — the only repo the loop watches/originates into.
ROBOCO_SELF_HEAL_CI_WORKFLOW ci.yml GitHub Actions workflow file to scope the CI signal to.
ROBOCO_SELF_HEAL_ORIGINATE_ENABLED false Second opt-in: on a regression, also open a fix task and dispatch it to the Main PM automatically (no manual start). The loop never merges or deploys — the fix ships through the normal gates (QA, PR review, your merge).
ROBOCO_SELF_HEAL_INTERVAL_SECONDS 1800 Seconds between telemetry passes.
ROBOCO_SELF_HEAL_MAX_OPEN_TASKS 3 Rolling cap on concurrently-open self-heal tasks.
ROBOCO_SELF_HEAL_MAX_PER_CYCLE 1 Max self-heal tasks originated in one cycle.

Multi-repo CI-watch — default off

The global switch arms the engine; each project opts in via ci_watch_enabled (+ optional ci_watch_workflow) in the edit-project dialog.

Variable Default Purpose
ROBOCO_CI_WATCH_ENABLED false Master switch for watching opted-in projects' CI. When off the engine never runs and no CI telemetry is fetched.
ROBOCO_CI_WATCH_DEFAULT_WORKFLOW ci.yml Workflow file to scope the CI signal to when a project sets no ci_watch_workflow of its own.
ROBOCO_CI_WATCH_INTERVAL_SECONDS 1800 Seconds between CI-watch passes.
ROBOCO_CI_WATCH_MAX_OPEN_TASKS 3 Rolling cap on concurrently-open CI-watch fix tasks per repo.
ROBOCO_CI_WATCH_MAX_PER_CYCLE 1 Max CI-watch fix tasks opened in one cycle.

Dependency-update bot — default off

The global switch arms the engine; each project opts in via dep_update_command (+ optional dep_update_paths) in the edit-project dialog. Detection is read-only — the command runs in a throwaway clone and only the lockfiles are diffed; the real repo is never mutated.

Variable Default Purpose
ROBOCO_DEP_UPDATE_ENABLED false Master switch for the dependency-update bot. When off nothing runs and no throwaway clone is made.
ROBOCO_DEP_UPDATE_INTERVAL_SECONDS 604800 Seconds between dependency-update passes (default weekly).
ROBOCO_DEP_UPDATE_MAX_OPEN_TASKS 3 Rolling cap on concurrently-open update-dependencies tasks per repo.
ROBOCO_DEP_UPDATE_MAX_PER_CYCLE 1 Max update-dependencies tasks opened in one cycle.

Gated release manager (default-off)

Variable Default Purpose
ROBOCO_RELEASE_MANAGER_ENABLED false Master switch for the gated release manager. When off the loop never runs and no release is proposed. Even on it only PROPOSES — the CEO approves before any publish.
ROBOCO_RELEASE_MIN_COMMITS 8 Minimum unreleased commits since the last tag before a release is proposed (a feat/security change also qualifies).
ROBOCO_RELEASE_MANAGER_INTERVAL_SECONDS 3600 Seconds between release-readiness assessment passes.
ROBOCO_RELEASE_CI_WORKFLOW ci.yml GitHub Actions workflow file the release fail-closed CI gate scopes to. Decoupled from ROBOCO_SELF_HEAL_CI_WORKFLOW — the release gate always resolves a named workflow and never uses all-workflows mode.

Organizational memory loop (default-off)

Variable Default Purpose
ROBOCO_ORG_MEMORY_ENABLED false Master switch for the org-memory loop. When off: legacy completion capture, no auto-inject, no playbook curation verbs.
ROBOCO_ORG_MEMORY_TOP_K 3 Max institutional-memory items injected into a briefing on claim.
ROBOCO_ORG_MEMORY_MIN_SCORE 0.6 Cosine-similarity floor for injected memory; below it, nothing is injected.

Next